An issue was discovered in the Merlin.PHP component 0.6.6 for Asuswrt-Merlin devices. An attacker can execute arbitrary commands because exec.php has a popen call. NOTE: the vendor indicates that Merlin.PHP is designed only for use on a trusted intranet network, and intentionally allows remote code execution

Project Subscriptions

Vendors Products
Asuswrt-merlin Project Subscribe
Rt-ac1900 Subscribe
Rt-ac1900 Firmware Subscribe
Rt-ac2900 Subscribe
Rt-ac2900 Firmware Subscribe
Rt-ac3100 Subscribe
Rt-ac3100 Firmware Subscribe
Rt-ac3200 Subscribe
Rt-ac3200 Firmware Subscribe
Rt-ac5300 Subscribe
Rt-ac5300 Firmware Subscribe
Rt-ac56u Subscribe
Rt-ac56u Firmware Subscribe
Rt-ac66u B1 Subscribe
Rt-ac66u B1 Firmware Subscribe
Rt-ac68p Subscribe
Rt-ac68p Firmware Subscribe
Rt-ac68u Subscribe
Rt-ac68u Firmware Subscribe
Rt-ac68uf Subscribe
Rt-ac68uf Firmware Subscribe
Rt-ac86u Subscribe
Rt-ac86u Firmware Subscribe
Rt-ac87 Subscribe
Rt-ac87 Firmware Subscribe
Rt-ac88u Subscribe
Rt-ac88u Firmware Subscribe
Rt Ac1900p Subscribe
Rt Ac1900p Firmware Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-09-16T22:41:30.909Z

Reserved: 2018-10-15T00:00:00.000Z

Link: CVE-2018-18320

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-10-15T06:29:00.763

Modified: 2024-11-21T03:55:42.310

Link: CVE-2018-18320

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses